# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=111

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 112

---

## [Searchng through 4 index fields with different clauses](https://discuss.elastic.co/t/searchng-through-4-index-fields-with-different-clauses/359710)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 0\
**Last updated:** [May 17, 2024, 11:35am UTC](https://discuss.elastic.co/t/searchng-through-4-index-fields-with-different-clauses/359710 "2024-05-17T11:35:20Z")

</div>

Hi everyone. I have a question of using script for searching query phrasy through 4 index fields with several different cluases in script. Each script will have it's own clauses. Script for searching through 4 fields: P…

---

## [I have a misunderstanding problem](https://discuss.elastic.co/t/i-have-a-misunderstanding-problem/359657)

<div class="topic-metadata">

**Author:** [@sossoulokoariel](https://discuss.elastic.co/u/sossoulokoariel)\
**Replies:** 2\
**Last updated:** [May 17, 2024, 11:04am UTC](https://discuss.elastic.co/t/i-have-a-misunderstanding-problem/359657 "2024-05-17T11:04:42Z")

</div>

Hi community I view the data on my Ubuntu client machine, and then on another Windows machine thanks to the same ELK supervision server, but I wonder why I also find the data processed on the Ubuntu machine on the Windo…

---

## [Backup over 7.17.4 and restoring on 8.x version. Is it possible?](https://discuss.elastic.co/t/backup-over-7-17-4-and-restoring-on-8-x-version-is-it-possible/359704)

<div class="topic-metadata">

**Author:** [@amrit\_singh](https://discuss.elastic.co/u/amrit_singh)\
**Replies:** 0\
**Last updated:** [May 17, 2024, 10:47am UTC](https://discuss.elastic.co/t/backup-over-7-17-4-and-restoring-on-8-x-version-is-it-possible/359704 "2024-05-17T10:47:43Z")

</div>

I am currently running on 7.17.4 version in containerized environment. Cluster has some heavy indexes so cant go with re-indexing as it may take days to transfer data. Can i restore backup taken over 7.17.4 directly over…

---

## [Ignore\_older concept is not working](https://discuss.elastic.co/t/ignore-older-concept-is-not-working/359531)

<div class="topic-metadata">

**Author:** [@babudurairaji](https://discuss.elastic.co/u/babudurairaji)\
**Replies:** 3\
**Last updated:** [May 17, 2024, 10:35am UTC](https://discuss.elastic.co/t/ignore-older-concept-is-not-working/359531 "2024-05-17T10:35:17Z")

</div>

Hi, ignore\_older concept is not working in our use case. Please find the below our use case : We took a backup of the Elasticsearch folder installed on your Windows server at 10 AM on May 15, 2024. Elasticsearch (ES)…

---

## [Not getting whole response when I search using java api client](https://discuss.elastic.co/t/not-getting-whole-response-when-i-search-using-java-api-client/359425)

<div class="topic-metadata">

**Author:** [@Rohini1](https://discuss.elastic.co/u/Rohini1)\
**Replies:** 13\
**Last updated:** [May 17, 2024, 9:37am UTC](https://discuss.elastic.co/t/not-getting-whole-response-when-i-search-using-java-api-client/359425 "2024-05-17T09:37:10Z")

</div>

I am using below code to search using java api client, SearchResponse searchResponse = esClient.search(searchRequest,Object.class); When I test it using postman - I am getting below response {"took":4,"timed\_out":fals…

---

## [Error 302 after Configuration alert msteam in watcher elasticsearch](https://discuss.elastic.co/t/error-302-after-configuration-alert-msteam-in-watcher-elasticsearch/358781)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 2\
**Last updated:** [May 17, 2024, 8:48am UTC](https://discuss.elastic.co/t/error-302-after-configuration-alert-msteam-in-watcher-elasticsearch/358781 "2024-05-17T08:48:01Z")

</div>

hi everyone ! Last week I have complete configure alert Microsoft Teams integration to watcher send\_to\_teams": { "webhook": { "scheme": "https", "host": "xxx.webhook.office.com", "port": 443, "method": "post", "…

---

## [Multiple filter (OR) in Lucene](https://discuss.elastic.co/t/multiple-filter-or-in-lucene/359645)

<div class="topic-metadata">

**Author:** [@RickT](https://discuss.elastic.co/u/RickT)\
**Replies:** 4\
**Last updated:** [May 17, 2024, 7:00am UTC](https://discuss.elastic.co/t/multiple-filter-or-in-lucene/359645 "2024-05-17T07:00:46Z")

</div>

hi all ! i'm trying to filter data with Lucene. I wish filtered the data having 2 fields exists. I tried with this code but it doesn't work : { "query": { "bool" : { "must": { "exists": { "field": "tota…

---

## [ElasticSearch renew certificate errors](https://discuss.elastic.co/t/elasticsearch-renew-certificate-errors/359452)

<div class="topic-metadata">

**Author:** [@Boodle](https://discuss.elastic.co/u/Boodle)\
**Replies:** 2\
**Last updated:** [May 17, 2024, 5:57am UTC](https://discuss.elastic.co/t/elasticsearch-renew-certificate-errors/359452 "2024-05-17T05:57:03Z")

</div>

Our SSL self signed elasticsearch certificates setup on docker had expired. Now Client application(Oracle Webcenter) is unable to make connection with Elasticsearch 7.17.6. Also trying to access elasticsearch cluster hea…

---

## [Why is security setup so ridiculously awkward?](https://discuss.elastic.co/t/why-is-security-setup-so-ridiculously-awkward/359587)

<div class="topic-metadata">

**Author:** [@jimmymacGA](https://discuss.elastic.co/u/jimmymacGA)\
**Replies:** 1\
**Last updated:** [May 17, 2024, 5:52am UTC](https://discuss.elastic.co/t/why-is-security-setup-so-ridiculously-awkward/359587 "2024-05-17T05:52:47Z")

</div>

With each release of Elasticsearch, the security setup process gets more and more complex and less and less stable. Anytime the ES server is restarted, Kibana loses its ability to authenticate without generating a new to…

---

## [\[Elasticsearch .NET\] Suggestions and Autocomplete](https://discuss.elastic.co/t/elasticsearch-net-suggestions-and-autocomplete/359676)

<div class="topic-metadata">

**Author:** [@hiilmiee](https://discuss.elastic.co/u/hiilmiee)\
**Replies:** 0\
**Last updated:** [May 17, 2024, 2:07am UTC](https://discuss.elastic.co/t/elasticsearch-net-suggestions-and-autocomplete/359676 "2024-05-17T02:07:19Z")

</div>

Does Elasticsearch .NET client supports suggestions and search-as -you-type ? saw this link but not sure if supported in the .NET client.

---

## [Continuous transform of a transform destination index](https://discuss.elastic.co/t/continuous-transform-of-a-transform-destination-index/359577)

<div class="topic-metadata">

**Author:** [@vstokarev](https://discuss.elastic.co/u/vstokarev)\
**Replies:** 1\
**Last updated:** [May 16, 2024, 9:48pm UTC](https://discuss.elastic.co/t/continuous-transform-of-a-transform-destination-index/359577 "2024-05-16T21:48:22Z")

</div>

I need to create a transform that will process the data from another transform's destination index to further aggregate the aggregated data. It works fine as a one-time job, but can it work continuously? Considering tha…

---

## [Allow\_auto\_create set to false in all templates after uprgade to 8.12.0](https://discuss.elastic.co/t/allow-auto-create-set-to-false-in-all-templates-after-uprgade-to-8-12-0/359654)

<div class="topic-metadata">

**Author:** [@logger](https://discuss.elastic.co/u/logger)\
**Replies:** 1\
**Last updated:** [May 16, 2024, 4:29pm UTC](https://discuss.elastic.co/t/allow-auto-create-set-to-false-in-all-templates-after-uprgade-to-8-12-0/359654 "2024-05-16T16:29:32Z")

</div>

Hi, I have seen another "Other thread with no answer" where the "allow\_auto\_create" is not working properly. In my cluster the setting is true by default: GET \_cluster/settings { "persistent": { "action": { …

---

## [Error Using AWS Built-in Fluent Bit to Send Logs to Elastic Cloud from EKS Fargate](https://discuss.elastic.co/t/error-using-aws-built-in-fluent-bit-to-send-logs-to-elastic-cloud-from-eks-fargate/359653)

<div class="topic-metadata">

**Author:** [@leohoang](https://discuss.elastic.co/u/leohoang)\
**Replies:** 0\
**Last updated:** [May 16, 2024, 3:54pm UTC](https://discuss.elastic.co/t/error-using-aws-built-in-fluent-bit-to-send-logs-to-elastic-cloud-from-eks-fargate/359653 "2024-05-16T15:54:21Z")

</div>

Hello everyone, I am using EKS Fargate and trying to use AWS built-in Fluent Bit to send logs to Elastic Cloud, but I am encountering the following error: { "log": "\[2024/05/16 14:35:17\] \[error\] \[output:es:es.0\] HT…

---

## [Applying SSL to Elasticsearch and Kibana: Connection refused on Kibana](https://discuss.elastic.co/t/applying-ssl-to-elasticsearch-and-kibana-connection-refused-on-kibana/358493)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 55\
**Last updated:** [May 16, 2024, 2:50pm UTC](https://discuss.elastic.co/t/applying-ssl-to-elasticsearch-and-kibana-connection-refused-on-kibana/358493 "2024-05-16T14:50:39Z")

</div>

Hello I just configured Elastic and Kibana to use SSL but Im getting a connection refused and errors about Kibana not being able to connect elasticsearch.yml: # Enable security features xpack.security.enabled: true x…

---

## [Only show and save logs more than 40 characters of line](https://discuss.elastic.co/t/only-show-and-save-logs-more-than-40-characters-of-line/359615)

<div class="topic-metadata">

**Author:** [@Suleman\_Ahmed](https://discuss.elastic.co/u/Suleman_Ahmed)\
**Replies:** 1\
**Last updated:** [May 16, 2024, 1:23pm UTC](https://discuss.elastic.co/t/only-show-and-save-logs-more-than-40-characters-of-line/359615 "2024-05-16T13:23:57Z")

</div>

Hello! Guys I need soluiton that How can I filter logs to only show and save logs contains more than 40 characters of line. If less I do not need it. Looking forward to it ASAP! Thanks Suleman

---

## [field.IpAddress returns loadbalancer IP](https://discuss.elastic.co/t/field-ipaddress-returns-loadbalancer-ip/358845)

<div class="topic-metadata">

**Author:** [@engin](https://discuss.elastic.co/u/engin)\
**Replies:** 2\
**Last updated:** [May 16, 2024, 7:42am UTC](https://discuss.elastic.co/t/field-ipaddress-returns-loadbalancer-ip/358845 "2024-05-16T07:42:01Z")

</div>

Hi, newbie on elastic here, I have several applications run on kubernetes. I am trying to get the real ips that comes from loadbalancer but all I see is the loadbalancer IP. { "\_index": "application-dev-2024.04.15", "…

---

## [Elastic Shards are Not Balanced Across Nodes](https://discuss.elastic.co/t/elastic-shards-are-not-balanced-across-nodes/359504)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 10\
**Last updated:** [May 16, 2024, 5:51am UTC](https://discuss.elastic.co/t/elastic-shards-are-not-balanced-across-nodes/359504 "2024-05-16T05:51:48Z")

</div>

Hi Team, Initially we had made a cluster of two nodes having six shards. Later we decided to add one more node to cluster, after adding node we can see that the cluster is in green state but the shards are not distribut…

---

## [ElasticSearch sort not working with es php library 8.2](https://discuss.elastic.co/t/elasticsearch-sort-not-working-with-es-php-library-8-2/359586)

<div class="topic-metadata">

**Author:** [@sajeeda](https://discuss.elastic.co/u/sajeeda)\
**Replies:** 0\
**Last updated:** [May 16, 2024, 4:24am UTC](https://discuss.elastic.co/t/elasticsearch-sort-not-working-with-es-php-library-8-2/359586 "2024-05-16T04:24:04Z")

</div>

Hi All, Trying to add sort option in query while retriving the data from Elasticsearch. Have been getting the below error PHP Fatal error: Uncaught Elastic\\Elasticsearch\\Exception\\ClientResponseException: 400 Bad Req…

---

## [Wait-until-merges-finish-after-index operations](https://discuss.elastic.co/t/wait-until-merges-finish-after-index-operations/359286)

<div class="topic-metadata">

**Author:** [@tommyd](https://discuss.elastic.co/u/tommyd)\
**Replies:** 8\
**Last updated:** [May 15, 2024, 9:33pm UTC](https://discuss.elastic.co/t/wait-until-merges-finish-after-index-operations/359286 "2024-05-15T21:33:52Z")

</div>

Hello Rally Gurus, I am testing my ES cluster using ESRally with openai\_vector track and I have a question about the "wait-until-merges-finish-after-index" operation. In the track README file, I see that there is this …

---

## [Use function\_score with index.sort to get top X and rescore on those](https://discuss.elastic.co/t/use-function-score-with-index-sort-to-get-top-x-and-rescore-on-those/359575)

<div class="topic-metadata">

**Author:** [@jmlucjav](https://discuss.elastic.co/u/jmlucjav)\
**Replies:** 0\
**Last updated:** [May 15, 2024, 8:19pm UTC](https://discuss.elastic.co/t/use-function-score-with-index-sort-to-get-top-x-and-rescore-on-those/359575 "2024-05-15T20:19:58Z")

</div>

Hi, I have a field 'mysort', I can declare it float, rankfeature...whatever I want. I use it for index sort: { "settings": { "index": { "sort.field": "mysort", "sort.order": "desc" } }, And…

---

## [The \_template API is erroneously creating my index as a data stream, which causes the \_bulk API to fail](https://discuss.elastic.co/t/the-template-api-is-erroneously-creating-my-index-as-a-data-stream-which-causes-the-bulk-api-to-fail/359568)

<div class="topic-metadata">

**Author:** [@lexicalunit](https://discuss.elastic.co/u/lexicalunit)\
**Replies:** 1\
**Last updated:** [May 15, 2024, 5:43pm UTC](https://discuss.elastic.co/t/the-template-api-is-erroneously-creating-my-index-as-a-data-stream-which-causes-the-bulk-api-to-fail/359568 "2024-05-15T17:43:04Z")

</div>

I'm trying to spin up a small working example of what we have in staging/production in a local dockerized setup. I've downloaded some representative data from my staging environment, now I just need to inject it into my …

---

## [SnipeIT Integration](https://discuss.elastic.co/t/snipeit-integration/359567)

<div class="topic-metadata">

**Author:** [@slama](https://discuss.elastic.co/u/slama)\
**Replies:** 0\
**Last updated:** [May 15, 2024, 5:03pm UTC](https://discuss.elastic.co/t/snipeit-integration/359567 "2024-05-15T17:03:19Z")

</div>

Has anyone integrated SnipeIT with Elastic SIEM?

---

## [New ElasticSearch setup](https://discuss.elastic.co/t/new-elasticsearch-setup/359552)

<div class="topic-metadata">

**Author:** [@Boodle](https://discuss.elastic.co/u/Boodle)\
**Replies:** 0\
**Last updated:** [May 15, 2024, 1:35pm UTC](https://discuss.elastic.co/t/new-elasticsearch-setup/359552 "2024-05-15T13:35:28Z")

</div>

We have a 3 node elasticSearch cluster setup on docker instance OS: Oracle Linux. This Elasticsearch version 7.17.6 is used by client application Oracle webcenter which has 7 Million documents stored on the Database. Re…

---

## [Abnormally high CPU usage for specific queries/dashboards](https://discuss.elastic.co/t/abnormally-high-cpu-usage-for-specific-queries-dashboards/359543)

<div class="topic-metadata">

**Author:** [@benpi](https://discuss.elastic.co/u/benpi)\
**Replies:** 2\
**Last updated:** [May 15, 2024, 12:43pm UTC](https://discuss.elastic.co/t/abnormally-high-cpu-usage-for-specific-queries-dashboards/359543 "2024-05-15T12:43:48Z")

</div>

Hi, i will start by sharing details regarding our infrastructure. We are running multiple Community Edition Elasticsearch clusters in parallel, all of which are connected via the "Remote Clusters" feature to a single in…

---

## [Using NFS mounted server in a DR environment as elasticsearch data path](https://discuss.elastic.co/t/using-nfs-mounted-server-in-a-dr-environment-as-elasticsearch-data-path/359534)

<div class="topic-metadata">

**Author:** [@charvi23](https://discuss.elastic.co/u/charvi23)\
**Replies:** 3\
**Last updated:** [May 15, 2024, 12:27pm UTC](https://discuss.elastic.co/t/using-nfs-mounted-server-in-a-dr-environment-as-elasticsearch-data-path/359534 "2024-05-15T12:27:49Z")

</div>

I have been trying to use production mount point as a NFS client and created a DR environment using NFS mount point as data path. Starting elasticsearch is giving error that it is not able to obtain lock as it doesn't e…

---

## [Elasticsearch Fails to start after restart](https://discuss.elastic.co/t/elasticsearch-fails-to-start-after-restart/359542)

<div class="topic-metadata">

**Author:** [@Hello1](https://discuss.elastic.co/u/Hello1)\
**Replies:** 1\
**Last updated:** [May 15, 2024, 12:24pm UTC](https://discuss.elastic.co/t/elasticsearch-fails-to-start-after-restart/359542 "2024-05-15T12:24:09Z")

</div>

because of memory my Elasticsearch service is down, i restarted the service but its inactive, i didn't change any thing, previously its worked.

---

## [Elasticsearch client uses up all ephermeral ports](https://discuss.elastic.co/t/elasticsearch-client-uses-up-all-ephermeral-ports/359510)

<div class="topic-metadata">

**Author:** [@kasinaat007](https://discuss.elastic.co/u/kasinaat007)\
**Replies:** 3\
**Last updated:** [May 15, 2024, 10:17am UTC](https://discuss.elastic.co/t/elasticsearch-client-uses-up-all-ephermeral-ports/359510 "2024-05-15T10:17:35Z")

</div>

After upgrading Azul Zulu JRE to the latest version, ES client uses up all ephemeral ports, other applications are not able to get ports to make outbound connections. OLD JRE Version : 1.8\_0\_282 NEW JRE Version : 1.8\_0…

---

## [JavaClientApi create SynonymsRule failed](https://discuss.elastic.co/t/javaclientapi-create-synonymsrule-failed/359501)

<div class="topic-metadata">

**Author:** [@yonghui](https://discuss.elastic.co/u/yonghui)\
**Replies:** 1\
**Last updated:** [May 15, 2024, 7:16am UTC](https://discuss.elastic.co/t/javaclientapi-create-synonymsrule-failed/359501 "2024-05-15T07:16:52Z")

</div>

PutSynonymRuleRequest.Builder builder = new PutSynonymRuleRequest.Builder(); builder.setId("my\_synonyms\_set") .ruleId("1") .synonyms("phone","苹果","华为"); return esSynonymsCl…

---

## [Reindex performance](https://discuss.elastic.co/t/reindex-performance/359362)

<div class="topic-metadata">

**Author:** [@post90](https://discuss.elastic.co/u/post90)\
**Replies:** 2\
**Last updated:** [May 15, 2024, 7:13am UTC](https://discuss.elastic.co/t/reindex-performance/359362 "2024-05-15T07:13:26Z")

</div>

I want to move subset of data from one index to another (could be same cluster or different). What are the advantages of using a \_reindex API instead of simply indexing the required data via logstash from the origin of d…

---

## [Field missing SBC - EgRFactor visualization on Elastic search v 7.7.0](https://discuss.elastic.co/t/field-missing-sbc-egrfactor-visualization-on-elastic-search-v-7-7-0/359365)

<div class="topic-metadata">

**Author:** [@melvinzoleta](https://discuss.elastic.co/u/melvinzoleta)\
**Replies:** 5\
**Last updated:** [May 15, 2024, 7:12am UTC](https://discuss.elastic.co/t/field-missing-sbc-egrfactor-visualization-on-elastic-search-v-7-7-0/359365 "2024-05-15T07:12:28Z")

</div>

Our company moved from version v 5.5.2 to Elastic search v 7.7.0 I am manually creating visualizations on Elastic search v 7.7.0 however the aggregation field SBC - EgRFactor is missing. Can somebody please advise wha…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=110)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=112)
